AVD with FSLogix with no On-prem AD.

Michael Novak 81 Reputation points
2024-01-29T13:21:48.9033333+00:00

Hi all, I have a client which does not have ANY on-prem AD (only local users on workgroup devices). They wish to implement Azure Virtual Desktop (AVD) with FSLogix functionality. According to this article, Clients must be Microsoft Entra joined or Microsoft Entra hybrid joined. Microsoft Entra Kerberos isn’t supported on clients joined to Microsoft Entra Domain Services or joined to AD only.

This feature doesn't currently support user accounts that you create and manage solely in Microsoft Entra ID. User accounts must be hybrid user identities, which means you'll also need AD DS and either Microsoft Entra Connect or Microsoft Entra Connect cloud sync.

I have understood that it is not possible to use Azure AD DS (Entra ID DS) without hybrid joined for FSLogix due to missing Entra Kerberos support.

I would like to understand if I can implement a cloud-only AVD with FSLogix with any combination of cloud services (i.e. Active Directory AD in Azure VM, Azure AD DS, Azure AD joined...) to achieve FSLogix functionality, or is there a hard requirement to have an on-prem hybrid joined devices and hybrid users to employ this functionality ? I am aware of the "hacks" with Fslogix cloud cache or storing storage account credentials in Windows clients, but I want solely an official supported route.

Would it be possible to build a new AD domain solely in Azure VM and then AD Connect sync the users to Azure AD? is this even supported? Many thanks.

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
9,040 questions
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Microsoft Entra | Other
{count} votes

Accepted answer
  1. Andreas Baumgarten 123.6K Reputation points MVP Volunteer Moderator
    2024-01-29T13:30:37.7733333+00:00

    Hi @Michael Novak , Azure AVD and FSLogix are supporting an Azure Entra ID cloud-only environment:

    FSLogix profile containers for Azure AD cloud only identities

    Set up FSLogix Profile Container with Azure Files and Active Directory Domain Services or Microsoft Entra Domain Services


    (If the reply was helpful please don't forget to upvote and/or accept as answer, thank you)

    Regards

    Andreas Baumgarten

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. vipullag-MSFT 26,487 Reputation points Moderator
    2024-02-02T03:31:16.5833333+00:00

    Hello Michael Novak

    Welcome to Microsoft Q&A Platform, thanks for posting your query here.

    I checked with internal team on this, feature to bring cloud identity support to FSLogix profile containers is planned and there is not ETA on this that can be shared now.

    As you mentioned the alternative is with a hybrid identity as documented, or the workarounds you referred. 

    Hope that clarifies.

    1 person found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.